Intermediate Infrastructure Security Engineer

  • GitLab
  • Remote, APAC
  • 23 Sep, 2024

Job Description

GitLab is an open core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become contributors, significantly accelerating the rate of human progress. This mission is integral to our culture, influencing how we hire, build products, and lead our industry. We make this possible at GitLab by running our operations on our product and staying aligned with our values. Learn more about Life at GitLab.

An overview of this role

As a member of the Infrastructure Security Team within the Product Security Department you will work with teams across GitLab to ensure that the components that comprise our public cloud infrastructure are built from the beginning with the resiliency and security expectations that our customers depend on to power their DevSecOps goals. 

We’re looking for an Intermediate Infrastructure Security Engineer to further our automation efforts in support of our upcoming GitLab Dedicated for Government product offering. You’ll have the opportunity to contribute to tooling that operates our FedRAMP environment, identify and develop remediations for infrastructure vulnerabilities, and partner with senior engineers to review upcoming project architectures to ensure that they are built to the rigorous standards we hold. 

What you’ll do in this role:

  • Support the Public Sector SRE team as a stable counterpart 
  • Own efforts securing GitLab's FedRAMP environment
  • Support other security teams as an Infrastructure SME
  • Identify and help mitigate security issues, misconfigurations, and vulnerabilities related to GitLab’s cloud, container and Kubernetes infrastructure
  • Build tooling to increase our visibility into environments to expedite vulnerability detection
  • Document best practices and remediations to help engineers learn from common vulnerability types
  • Partner with senior engineers to review new architectures and projects and provide feedback cross-functionally 
  • Fulfill the Product Security Division Mission of securing GitLab Infrastructure with our own product (“dogfooding”)   

You should apply if you bring:

  • Hands-on experience with public cloud providers (ex. AWS, GCP, Azure)
  • Development experience with Ruby, Python, Go
  • Experience with Infrastructure-as-Code (IaC) tools (ex. Terraform, Ansible, Chef)
  • Knowledge of the Linux operating system
  • Familiarity with containers (Docker) and orchestration platforms (Kubernetes)
  • An interest in Information Security
  • Demonstrated experience working collaboratively with cross-functional teams.
  • Proficiency to communicate over a text-based medium (Slack, GitLab Issues, Email) and can succinctly document technical details
  • Share our values, and work in accordance with those values

Also, we know it’s tough, but please try to avoid the ​​confidence gap​.​​ You don’t have to match all the listed requirements exactly to be considered for this role. Our hiring process for this Infrastructure Security Engineer position typically follows four stages. The details of this process and our leveling structure can be found on our job family page

Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process.  

Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us.

GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.